When the Legal Basis Crumbles: Why Data Protection Is a Business Issue

10.08.2026

Teilen

259 times. That is how often the text of the EU-U.S. Data Privacy Framework refers to a single word: independence. This refers to the independence of the Federal Trade Commission, the U.S. agency tasked with overseeing data protection. The entire structure of the agreement rests on this assumption.

This assumption no longer holds. The U.S. Supreme Court has ruled that the president may dismiss the agency’s head. As a result, the assumed independence is no longer a legal fact. It has become a matter of political goodwill. Among experts, the agreement has since been widely regarded as beyond salvage.

For companies in Europe, this is not a legal footnote. It is a business issue.

 

The pattern is familiar

We wrote about natural gas here a few weeks ago. For decades, it was reliable, affordable, and convenient—until control suddenly shifted elsewhere and dependence turned into a strategic risk. The technology was never the problem. The pipelines worked.

This pattern is repeating itself with transatlantic data transfers, and there are already examples of it. The Chief Prosecutor of the International Criminal Court was denied access to his services. Individual judges and members of nongovernmental organizations faced similar situations. In none of these cases did the technology fail. It simply became clear who holds the power to turn the switch on and off.

 

Two to three years is not a reprieve

Formally, the DPF remains in effect for the time being. Either the European Commission will repeal it, or it will be overturned by the European Court of Justice. Realistically, this process is likely to take two to three years.

This time can be used in two ways. One can sit it out and hope that a political solution will emerge. Or you can use it as a window of opportunity to systematically bring your own data processing into compliance with the law. The difference between these two approaches isn’t apparent today. It will become clear on the day the ruling is issued. Those who wait until then to start will be migrating under time pressure. And in regulated environments, time pressure is the most costly operating condition there is.

 

„You can’t patch legal foundations. If data processing is only permissible for as long as an adequacy decision remains in effect, then we’re talking about an availability risk. That’s exactly how we treat it—as a matter of the operating model, not as a matter of contract structure.” Tobias Lehner, CTO of synaforce

 

Standard contractual clauses do not solve the problem

A common reflex is to fall back on standard contractual clauses if the DPF fails. That falls short. Even standard contractual clauses presuppose that a level of protection that is essentially equivalent can be achieved in the recipient country. It is precisely this point that is called into question by the FTC’s decision. A contract binds the contracting party. It does not bind the authority seeking access to the data.

The real conflict runs deeper. The right to protection under the GDPR and the right of access claimed by U.S. institutions are fundamentally incompatible. No agreement in the world can resolve this contradiction through clever wording.

 

What this means in practice

KRITIS and regulated sectors: What matters here is whether a transfer is verifiably permissible in an audit. Where processing, storage, and operations take place within the EU legal jurisdiction and are certified under ISO/IEC 27001, BSI C5, ISAE 3402, and DIN EN 50600 CAT III, the discussion regarding adequacy decisions is completely moot.

Healthcare: Patient data is considered “special categories of personal data” under Article 9 of the GDPR. For hospitals and medtech companies, the DPF debate is therefore directly relevant to their operations. Those who rely on auditable operating models in this area are structurally unaffected by the expiration of an agreement.

Software manufacturers and SaaS providers: Anyone offering an application as a service is also responsible for the legal basis of the underlying infrastructure and is increasingly being asked about this by customers. A European processing location is thus evolving from a compliance detail into a sales argument.

IT system integrators: The question “Where is our customers’ data actually stored?” is being asked more frequently now than it was a year ago. Those who can provide a verifiable answer to this question are having a different conversation.

 

Sovereignty does not mean isolation

It’s not about ruling out U.S. technology across the board. The point is to avoid entering into dependencies that cannot be broken in an emergency. That is precisely why, at synaforce Cloud, we rely on OpenStack with KVM as an open industry standard, on hybrid architectures without forced full migration, and on data centers in Germany and Switzerland. Take Hofkirchen, for example, which meets DIN EN 50600 CAT III, DIN ISO 50001, has a PUE of 1.1, and is powered 100 percent by renewable energy sources.

It’s not just the location that makes the difference. What’s crucial is the combination of the European legal framework, open technology, and an operating model that remains transparent.

 

The path to that goal is day-to-day work

Having a data center in Europe is a prerequisite. The real work begins after that.

That’s why our services don’t stop at providing infrastructure. We operate the systems on a day-to-day basis, with defined responsibilities, monitoring, support, and the documentation required for audits. And we guide the transformation toward that goal. In many projects, we carry it out ourselves.

That’s the point where a robust infrastructure differs from robust operations. You can simply sign up for a platform. An operational model, however, must remain viable over the years—even as requirements change, systems grow, and an auditor asks specific questions.

 

Conclusion

In the current political debate, there are proposals to supplement a less vulnerable agreement with regulations that provide incentives to process personal data within the EU legal framework. This would also benefit the economy—in this case, the European economy.

We share this assessment and would like to add a practical point. Companies do not have to wait for these regulations. The infrastructure needed to operate data entirely within the European legal framework already exists. It is auditable, scalable, and compatible with current systems.

It is important to have realistic expectations. Digital sovereignty is not a switch that can be flipped. After all, the very question at hand is who controls that switch. Sovereignty is built through many small steps: one application at a time, one dataset at a time, with clear priorities and without disrupting operations. No big leap. Many small steps leading in the same direction.

That’s exactly how we’ve set things up at synaforce. Sovereignty isn’t created by an agreement. It’s created through decisions about our own operations—and by the people who manage those operations every day.

 

Would you like to know which of your workloads would be affected by the removal of the DPF and in what order migration would make sense? Please contact us.

 

#synaforce #DigitalSovereignty   #GDPR  #DataProtection #SovereignCloud  #OpenStack